Security Center

You've worked hard to build your business.

We're committed to helping you protect it.

Our team works diligently to safeguard your BILL account with industry-accepted best practices, including advanced security tools, training on the latest policies and procedures, and continuous monitoring.
Get Started
Header image

Report suspicious activity

Notice something fishy with your BILL account, or believe your information has been compromised?

Let us know

Report phishing scams

Receive a suspicious email from someone claiming to represent BILL?

  • Don't reply to it
  • Don't click on any links
  • Don't open any attachments

Forward the email immediately to phishreport@hq.bill.com

Stay on guard

BILL is designed with your privacy and security in mind. We are committed to keep your information safe—but we need your help, too.

Listed below in BILL Protections and Security Measures, you can find various levels of controls we have in place to help guard your money and sensitive information.

You can also read various best practices, tips, and resources to help keep your account, data, and identity safe under Securing your accounts and transactions, and Protecting your devices and email accounts.

BILL Protections and Security Measures

We're enhancing our security with you in mind.

Application Protections

BILL helps protect against unauthorized access to your account by:
  • Enforcing a strong password policy
  • Applying 2-Factor Authentication
  • Sending login data over a secure channel
  • Automatically logging out customers after a period of inactivity
  • Educating our customers on the risks of business email compromise schemes
  • Enforce separation of duties with role-based access that lets you control who can enter, approve, and pay bills.
  • Automatically keep a record of all AP activity with a timestamped audit trail that cannot be altered, including original bills, review notes, approvals, payments, and remittance details for each transaction; then easily access that documentation for internal, vendor, and auditor inquiries.

Payment Protections

  • Reduce risks from check theft by paying vendors with digital payments or checks that are sent by BILL on your behalf, rather than keeping blank check stock on your premises and exposing your bank information on checks you send.
  • BILL applies Positive Pay to reduce the risk of check fraud; the bank matches the check issued with the check presented for payment.
  • Keep your bank account information private from vendors by making digital payments through the BILL account.

Network Protections

  • BILL uses security software, intrusion detection and prevention appliances, and network monitoring technology to detect and prevent unauthorized electronic access to our servers.

Data Protections

  • BILL applies an additional level of encryption to protect access to sensitive customer data from malicious applications.
  • We use Transport Layer Security (TLS) and industry standard cipher suites to protect customer data during transit over the internet.
  • BILL replicates production data from the primary site to the co-location facility for disaster recovery scenarios.

Physical Protections

  • BILL servers and network infrastructure are hosted at secure data center facilities managed by leading certified data center providers.
  • All our employees undergo background checks and data security and privacy training.
  • We have a formal vendor management program to manage third-party risks.

Compliance Protections

  • BILL undergoes an annual SOC 1 and SOC 2 Type II Audit by a leading national CPA Firm.
  • BILL partners with a PCI certified vendor for credit card payments.
  • We have adopted an Anti-Money Laundering (AML)/Office of Foreign Assets Control (OFAC) Program, which is designed to prevent the BILL Service from being used for purposes of money laundering, terrorist financing, violating or subverting OFAC sanctions, or for other illegal purposes.

Securing your accounts and transactions

Best practices for Administrators/Employees

  • Do not share passwords, PIN, security tokens or any other account credentials. That includes reusing the same credentials elsewhere or sharing them with another person. Keep them secure.
  • Always use strong and unique passwords that are not easily guessable. An 8 characters or longer, random password that contains a combination of upper and lower case letters, numbers and symbols is much harder to break.
  • Review account transactions daily and reconcile frequently.
  • Avoid using public computers to access your account—even if additional security measures have been taken.
  • Practice security principles of least privilege and separation of duties. BILL provides granular, role based access control capabilities in the product. Use them to carefully grant and monitor access. Grant minimal access needed for employees to do the assigned job duties. Promptly remove the access when no longer needed. Assign different roles to different employees so that a single person alone can not compromise the transaction workflow.
  • Building a security culture where everyone understands their part in keeping an organization secure goes a long way. Train everyone in the company on best practices in information security, not just financial personnel. Identify regular opportunities to routinely discuss security best practices, such as staff meetings or other group check-ins.
  • Set up Multi-Factor Authentication to help further protect your account from unauthorized log-ins.

Protecting your devices and email accounts

Best practices for Administrators

  • Install reputable anti-virus and anti-malware software and update it frequently. Most modern software updates automatically.
  • Keep operating systems, browser, and email patches up to date.
  • Keep your web browser software up to date by regularly installing the most recent version.
  • Use reputable network and desktop firewall solutions.
  • Require and monitor that users sign off their computer or employ a lock screen when not in use.
  • Consider disabling CD, DVD and USB drives on all computers where these drives are not needed.

Best practices for Accountants/ Employees

  • Do not click on links or attachments in an email that seem suspicious, and do not reply to it. Forward all suspicious emails directly to your IT and/or Risk team.
  • Be suspicious of requests for secrecy or pressure to take action quickly.
  • Watch for bogus email messages disguised to appear as authentic:
    - Fraudsters commonly spoof legitimate email domains with ones that look similar (e.g., name@busines.com or name@business.net instead of name@business.com).
    - Hover over an email address to ensure it isn’t being masked as something it’s not.

Responsible Disclosure Program

We take security seriously at BILL and are deeply appreciative of the role that security researchers play in improving the security posture of our product and platform.

We partner with HackerOne to facilitate responsible disclosure of any security issues impacting BILL services. If you believe you have discovered a security vulnerability that you would like to report, please submit using this form.